Remove Glacier. Description and removal instructions

 
Title: Glacier

Type: Remote Administration Tools
Severity scale:Glacier severity is 50  (50 / 100)
 
This RAT originated in China. The author is a hacker called Y2KZERO. A lot of versions (Glacier 0.0, Glacier 1.0, Glacier 1.2, Glacier 2.0, Glacier 2.2, Glacier 2000, Glacier 2002, Glacier 2002 XP, Glacier 3.0, Glacier 3.3, Glacier 4.1, Glacier 5.3, Glacier 5.5, Glacier 5.5b, Glacier 6.0, Glacier 8.0, Glacier 8.0 Beta2, Glacier 8.2, Glacier 8.4, Glacier 9.11, Glacier ROSE, Glacier XX4) appeared from October 1999 to July 2004. The virus is written in Delphi and compressed with UPX. The infection peaked in such countries as Lithuania and United States. This program was designed for illegal controlling of other people's computers. The hacker infects the victim's machine via the e-mail or File and Print Sharing with a "server" program. He can later access the infected machine via a "client". The functions of a RAT may vary, depending on the needs of the hacker. Note: version 1.0 can't be classified as very dangerous, because the "server" is visible in System Tray.


Glacier properties:
• Allows remote user connection
• Hides from the user
• Stays resident in background

Automatic Glacier removal:

remover for Glacier

Glacier manual removal:

Kill processes:
2003.exe, backdoor.g_door.b_(183).exe, backdoor.g_door.b_(222).exe, bh5.5b.exe, client.exe, g_client).exe, g_client.exe, g_clinet.exe, g_server.exe, garu.exe, ldb.exe, mma.exe, pucca.exe, server.exe, [system, root]\\system\\, .exe, [system, root]\\system\\lfp.exe, [system, root]\\system\\rnudll32.exe, [system, root]\\system\\shellscrap.exe, [system, root]\\system\\sysdll32.exe, [system, root]\\system\\sysexecr.exe, [system, root]\\system\\sysexplr.exe, [system, root]\\system\\sysrun32.exe, [system, root]\\system\\system32.exe, [system, root]\\system\\winabc.exe
Delete registry values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\sysdll32.dll
Unregister DLLs:
[system root]\\system\\tel.dll

Delete files:
2003.exe, backdoor.g_door.b_(183).exe, backdoor.g_door.b_(222).exe, bh5.5b.exe, client.exe, g_client).exe, g_client.exe, g_clinet.exe, g_server.exe, garu.exe, ldb.exe, mma.exe, operate.ini, pucca.exe, readme.txt, readmenow.txt, server.exe, setup.ini, [system root]\\system\\ .exe, [system root]\\system\\lfp.exe, [system root]\\system\\rnudll32.exe, [system root]\\system\\shellscrap.exe, [system root]\\system\\sysdll32.exe, [system root]\\system\\sysexecr.exe, [system root]\\system\\sysexplr.exe, [system root]\\system\\sysrun32.exe, [system root]\\system\\system32.exe, [system root]\\system\\tel.dll, [system root]\\system\\winabc.exe, [system root]\\temp\\psw.tmp, ttian.net.htm

Other programs to remove Glacier:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 27/03/05
Information updated: 27/03/05

Additional resources related to Glacier:

Attention: If you know or you have a website or page about Glacier removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Glacier parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: